An AI agent built a working exploit for this macOS flaw in four hours

Attackers are exploiting the macOS Screen Sharing flaw to gain root and install Monero miners, the Dutch cyber agency says. A security firm built working exploits for it using an AI agent, in four hours. Apple has patched it, and two national agencies disagree on how severe it is.


An AI agent built a working exploit for this macOS flaw in four hours
Image Credits Credit: Canva

A security company built working exploits for two pre-authentication root bugs in macOS. It took four hours.

The firm, Calif, used an AI agent. It now withholds technical details of one of those bugs, CVE-2026-65400, until most Macs carry the patch. The reason is the speed. Producing the exploit was too easy.

Attackers are using that bug right now.

What is happening to unpatched Macs

The Dutch national cyber security centre revised its advisory on 12 August. It had received a report of active abuse. The affected systems all had port 5900 reachable from the internet.

“In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed,” the agency said.

Every confirmed case. Root, then a miner.

The macOS Screen Sharing flaw lets an attacker on the network authenticate to the remote desktop service without valid credentials. Apple calls it an authentication issue and says improved state management resolves it. Screen sharing is the built-in feature that lets someone else watch your screen and drive your keyboard and mouse.

Switch it on and the macOS firewall opens port 5900.

Monero is the default coin for this kind of attack, for two reasons. Its transactions obscure sender, recipient, and amount, where Bitcoin writes them to a public ledger. Its mining also suits ordinary CPUs, which makes a hijacked laptop worth something. TechRadar expects the attackers ran XMRig, the most common Monero miner, though nobody has confirmed that.

The four-hour exploit is the part that matters

Cryptomining is the visible damage. It is also the least of it. Ars Technica named the obvious escalation: nothing stops an attacker holding root from installing something that steals credentials instead.

The faster-moving problem is how quickly a patch became an exploit. Calif reverse-engineered Apple’s out-of-band update because the update itself was a signal. Apple does not ship out of band unless something is critical, the firm noted.

From there an AI agent produced working exploits for two separate pre-auth remote root bugs, inside four hours.

This keeps happening. We reported in July that Microsoft credited AI with finding a record crop of flaws.

Then researchers showed AI-discovered vulnerabilities moving into real exploitation. Days later the same pattern hit WordPress.

Two weeks ago it reached Zoom and its annotations. Now it is Apple. One startup raised $60mn on the premise that patching cannot keep up.

Two agencies, two very different scores

Here the record gets messy, and precision matters.

The Dutch agency scores CVE-2026-65400 at 7.1 under CVSS version 3. That reads as high, not critical. Ars Technica used the same figure.

CISA put it at 9.8, critical, through the enrichment programme that feeds the National Vulnerability Database. The Hacker News and several other outlets ran with that number.

NIST has not assessed it at all. Its NVD entry still says no assessment has arrived.

So two national agencies disagree by 2.7 points on one bug. The body that normally settles such things has not ruled. And the agency scoring it lower is the agency that found it being exploited.

One further caution. TechRadar reported the score as 9.6. That figure matches no source we could find.

How many Macs are exposed

A researcher using the handle osxreverser scanned for open screen sharing hosts. He counted roughly 40,000 reachable from the internet. Almost half sat in the United States. Most were residential addresses, though the list took in university systems and company servers.

He also raised a separate issue. He says the more serious flaw is a pre-auth bug in the screen sharing daemon needing nothing but an IP address, which Apple fixed in macOS 26.6 rather than 26.6.1.

He never reported it to Apple. He cited his own long history with the company.

What Apple did, and when

Apple published its advisory on 6 August. It credited Alfredo Pesoli of the security firm Bynario. Fixes shipped in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

Details reached the public at Black Hat the same week. The Dutch agency first advised on 7 August, then revised on 12 August, once a public proof of concept existed and abuse had started.

Pesoli had already documented a related weakness. A legacy authentication path let a remote viewer make macOS read protected files as root, and create files as root. He used the second half to write a sudoers policy and turn a file copy into remote root command execution.

Other screen sharing bugs went out in macOS 26.6 shortly before, including one rated 9.8 that let an app intercept another process’s network connections.

What to actually do

Install the update. That closes it.

If you cannot patch today, turn screen sharing off. Open System Settings, go to General, then Sharing. Toggle it off, and switch it on only for the length of a session.

Blocking port 5900 at the router or firewall helps. Treat that as a fallback rather than a fix.

Practitioners have long advised keeping 5900 shut even while using screen sharing, and reaching machines over a VPN or an SSH tunnel instead. Ars Technica made the fair point that those alternatives sit beyond most users.

Plenty remains unsaid. Nobody has published when the attacks started, how many machines took a hit, or whether anyone exploited the flaw before Apple shipped the patch. Nobody has shown use beyond mining either. On current evidence that last one holds. It is also the part most likely to change.

Get the TNW newsletter

Get the most important tech news in your inbox each week.